Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=nxxnxx.info
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://nxxnxx.info/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: nxxnxx.info
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Sun, 14 Sep 2014 16:50:32 GMT
Server: nginx
Vary: Accept-Encoding,Cookie
Content-Type: text/html; charset=UTF-8
WP-Super-Cache: Served supercache file from PHP
X-Powered-By: PHP/5.4.19
GET / HTTP/1.1
Host: nxxnxx.info
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Sun, 14 Sep 2014 16:50:32 GMT
Server: nginx
Vary: Accept-Encoding,Cookie
Content-Type: text/html; charset=UTF-8
WP-Super-Cache: Served supercache file from PHP
X-Powered-By: PHP/5.4.19
Second query (visit from search engine):
GET / HTTP/1.1
Host: nxxnxx.info
Referer: http://www.google.com/search?q=nxxnxx.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: nxxnxx.info
Referer: http://www.google.com/search?q=nxxnxx.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://nxxnxx.info/ | 200 OK Content-Length: 27732 Content-Type: text/html | clean |
http://nxxnxx.info/wp-content/themes/WPTube3/js/jquery-1.3.2.min.js | 200 OK Content-Length: 57254 Content-Type: application/x-javascript | clean |
http://nxxnxx.info/wp-content/themes/WPTube3/js/jqueryslidemenu/jqueryslidemenu.js | 200 OK Content-Length: 2151 Content-Type: application/x-javascript | clean |
http://nxxnxx.info/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/x-javascript | clean |
http://nxxnxx.info/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://nxxnxx.info/wp-content/plugins/fake-traffic-blaster//js/ftblaster.js?ver=1.0 | 200 OK Content-Length: 656 Content-Type: application/x-javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.2.6/jquery.min.js | 200 OK Content-Length: 55740 Content-Type: text/javascript | clean |
http://demonpictures.info/js/clickunder.js | 200 OK Content-Length: 205 Content-Type: application/x-javascript | clean |
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12388 Content-Type: application/javascript | clean |
http://adspaces.ero-advertising.com/adspace/225116.js | 200 OK Content-Length: 1562 Content-Type: application/javascript | clean |
http://nxxnxx.info/wp-content/plugins/acurax-on-click-pop-under/js.php | 200 OK Content-Length: 2816 Content-Type: text/html | clean |
http://nxxnxx.info/test404page.js | 404 Not Found Content-Length: 9710 Content-Type: text/html | clean |
http://nxxnxx.info/nxx/%d8%a7%d9%84%d8%ac%d9%86%d8%b3-%d8%a7%d9%84%d8%ab%d8%a7%d8%a8%d8%aa | 200 OK Content-Length: 26706 Content-Type: text/html | clean |
http://nxxnxx.info/nxx/%d8%a7%d9%84%d9%85%d8%b9%d9%84%d9%85 | 200 OK Content-Length: 25978 Content-Type: text/html | clean |
http://nxxnxx.info/nxx/%d8%a7%d9%85%d8%b1%d8%a3%d8%a9-%d8%b3%d9%85%d8%b1%d8%a7%d8%a1 | 200 OK Content-Length: 26642 Content-Type: text/html | clean |